HTML Entity Encoder & Decoder — Free
Runs 100% in your browser — your files never leave your device.
Literal angle brackets, ampersands, and quotes can turn copied content into markup. Encode them as safe HTML entities, or decode named and numeric entities from existing source back into readable text. The transformation runs locally.
How it works
- 1
Select the direction
- 2
Enter text or entities
- 3
Copy the safe result
About this tool
What entities protect
Characters like <, >, and & are markup syntax in HTML. Text containing them raw turns into accidental tags or broken parsing. Encoding converts them to named (< &) or numeric (<) entities that render as the characters instead of executing as structure.
Escape versus decode
Encode text before placing it inside HTML where it must display literally — user content, code samples, angles in prose. Decode when reading source that arrived with entities and you need the plain characters back. Round trips are lossless: encode → render → decode returns the original text.
The security angle
Escaping user content before inserting it into HTML is the front-line defense against XSS: an escaped <script> renders as visible text instead of running. Escaping is one layer — keep it, but never treat it as your only one.
Frequently asked questions
When should I use named versus numeric entities?
Named entities (&, <, ) read better in source for the common characters. Numeric forms (<, <) exist for every code point and survive when a named entity is unavailable.
Do I escape quotes in text content?
Quotes only matter inside attribute values — escape them there. In text content, < and & are the critical ones.
Why does my decoded text show strange characters?
The source encoded non-ASCII characters as numeric entities — the decode is correct, and the characters were always there. A character-encoding mismatch in the viewer is the usual culprit.